logo

CVE-2026-3854 GitHub flaw enables remote code execution

ID: a7368a70-0916-54f4-8019-92eb0896d07a

STIX ID: report--a7368a70-0916-54f4-8019-92eb0896d07a

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2026-04-28

Date Updated: 2026-04-28

Author: Pierluigi Paganini

...
...

Critical command-injection vulnerability CVE-2026-3854 in GitHub allows an attacker with push access to achieve remote code execution by injecting crafted push option values into internal metadata. The issue affects GitHub Enterprise Cloud and Enterprise Server variants, can lead to full system compromise or exposure of repositories on shared storage, was patched quickly by GitHub, and researchers reported no confirmed in-the-wild exploitation beyond tests.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.